Improper access control in 3rd Generation Intel Xeon Scalable Processors - CVE-2021-33117
Published: May 17, 2022
Vulnerability identifier: #VU63349
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-33117
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to improper access restrictions. A local user can bypass implemented security restrictions and gain access to sensitive information.
Affected software
3rd Generation Intel Xeon Scalable Processors
Dell PowerEdge BIOS 15G
Dell PowerEdge BIOS 14G
Amazon Linux AMI
F5OS
Ubuntu
microcode_ctl
intel-microcode (Ubuntu package)
Dell PowerEdge BIOS 13G
VxFlex ESXi
Integrated System for Microsoft Azure Stack Hub
Dell PowerEdge BIOS 15G
Dell PowerEdge BIOS 14G
Amazon Linux AMI
F5OS
Ubuntu
microcode_ctl
intel-microcode (Ubuntu package)
Dell PowerEdge BIOS 13G
VxFlex ESXi
Integrated System for Microsoft Azure Stack Hub
How to mitigate CVE-2021-33117
Install updates from vendor's website.
Dell PowerEdge BIOS 15G - update to 1.6.5
microcode_ctl - update to 2.1-53
Dell PowerEdge BIOS 14G - update to 2.14.2
Dell PowerEdge BIOS 13G - update to 2.15.0
intel-microcode (Ubuntu package) - addressed in versions 3.20220510.0ubuntu0.16.04.1+esm1, 3.20220510.0ubuntu0.18.04.1, 3.20220510.0ubuntu0.20.04.1, 3.20220510.0ubuntu0.21.10.1, 3.20220510.0ubuntu0.22.04.1
VxFlex ESXi - update to 6.7 P07
Integrated System for Microsoft Azure Stack Hub - update to 2210
microcode_ctl - update to 2.1-53
Dell PowerEdge BIOS 14G - update to 2.14.2
Dell PowerEdge BIOS 13G - update to 2.15.0
intel-microcode (Ubuntu package) - addressed in versions 3.20220510.0ubuntu0.16.04.1+esm1, 3.20220510.0ubuntu0.18.04.1, 3.20220510.0ubuntu0.20.04.1, 3.20220510.0ubuntu0.21.10.1, 3.20220510.0ubuntu0.22.04.1
VxFlex ESXi - update to 6.7 P07
Integrated System for Microsoft Azure Stack Hub - update to 2210
External References
Related Security Bulletins
- Information disclosure in 3rd Generation Intel Xeon Scalable Processors
- Information disclosure in F5OS Intel processor
- Ubuntu update for intel-microcode
- Ubuntu update for intel-microcode
- Multiple vulnerabilities in Dell PowerEdge BIOS
- Multiple vulnerabilities in Dell Integrated System for Microsoft Azure Stack Hub
- Multiple vulnerabilities in Dell VxFlex ReadyNode and Dell VxFlex ESXi
- Amazon Linux AMI update for microcode_ctl